MSFN Forum: Bropia.A, a new MSN Messenger worm on the loose! - MSFN Forum

Jump to content



Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

Bropia.A, a new MSN Messenger worm on the loose! Rate Topic: -----

#1 User is offline   dwergs 

  • Group: Members
  • Posts: 5
  • Joined: 20-January 05

Posted 20 January 2005 - 10:03 AM

Based on numerous reports from visitors of Mess.be, a new virus seems to be propagating itself rapidly through MSN Messenger.

F-Secure identifies the worm as Bropia.A, other antivirus software (like including Kaspersky) labels it IM-Worm.Win32.VB.a.

When received and executed by the victim, the worm places itself in the C directory with a random filename like:

sexy_bedroom.pif
drunk_lol.pif
naked_party.pif
webcam_(random number).pif
love_me.pif and similar looking names.

It then automatically sends itself to active MSN Messenger contacts. It also drops and executes oms.exe, a variant of Rbot, which copies itself as lexplore.exe and adds two registry keys so it will be executed at next system startup. The bot can be used as a backdoor, logging keystrokes, relaying spam and for various other purposes and is therefor a huge security threat to your system. Brobia.A can also disable mouse right button and manipulate Windows mixer volume settings.

Posted Image

If you receive a file transfer request for such a file, press ALT-D or click Decline. Don't ever execute the file. If you did, delete the file immediately and permanently from your system (My Received Files and C drive) and take necessary security measures. For more information, visit F-Secure.

Source: Mess with MSN Messenger


#2 User is offline   Martin L 

  • 我叫马丁
  • Group: Patrons
  • Posts: 1,684
  • Joined: 09-July 03

Posted 20 January 2005 - 12:44 PM

thanks :) posted at frontpage

#3 User is offline   MCT 

  • MSFN Junkie
  • PipPipPipPipPipPipPipPipPip
  • Group: Members
  • Posts: 3,288
  • Joined: 19-May 04

Posted 20 January 2005 - 12:51 PM

thanks 4 the info

#4 User is offline   gamehead200 

  • SEARCH!!! SEARCH!!!
  • Group: Super Moderator
  • Posts: 7,019
  • Joined: 02-September 02
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 20 January 2005 - 12:53 PM

Yeah, a bunch of my friends have this virus... Basically, what is does is the following:

- Run it.
- Puts in a registry value to start on startup.
- There is a file in the system32 folder (exe).
- Logs you in and out of MSN and spreads.

#5 User is offline   prathapml 

  • Follow the rules please :-)
  • Group: Patrons
  • Posts: 6,791
  • Joined: 14-November 03
  • OS:Windows 7 x64
  • Country: Country Flag

Posted 20 January 2005 - 01:08 PM

:fear: I've got logged in and out once. :fear:
And I'm not even sure if its happening because of my ISP or this worm... :fear:



EDIT:
No worries!
I just noticed that it uses .PIF to spread. And I have prevented precisely this sort of situation by disabling hostile file-types (associate *.PIF to text-file) so its totally harmless. :D

Share this topic:


Page 1 of 1
  • You cannot start a new topic
  • You cannot reply to this topic

1 User(s) are reading this topic
0 members, 1 guests, 0 anonymous users



All trademarks mentioned on this page are the property of their respective owners
Copyright © 2001 - 2011 msfn.org
Privacy Policy